Description
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-09-08
Score: 10 Critical
EPSS: 3.3% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Adobe Campaign Classic suffers from an OS command injection flaw that allows an attacker to run arbitrary code in the context of the current user. Because the vulnerability does not require user interaction, exploitation can occur automatically once the application processes malicious input. This weakness, identified as CWE‑78, directly compromises confidentiality, integrity, and availability of the system.

Affected Systems

Adobe Campaign Classic. Versions 7.4.4 build 9400 and 9401 are specifically affected per the CPE data; other deployments may also be at risk if they lack the patch.

Risk and Exploitability

The CVSS score of 10 signals a maximum severity vulnerability with the potential for complete system takeover. The EPSS score of 3% indicates a low but nonzero probability that this vulnerability is actively exploited. The fact that the flaw only needs the application to process data and that the scope is changed means that on exploitation the attacker could immediately alter or compromise the application’s entire environment. The issue is not listed in the CISA KEV catalog, but its high technical score and lack of user interaction barriers still make it a critical threat worthy of rapid remediation.

Generated by OpenCVE AI on September 25, 2026 at 00:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Adobe patch released for Adobe Campaign Classic as outlined in the Adobe Campaign Classic Security Advisory, following the guidance on the Adobe Help Portal.
  • Restrict the parameters that are passed to operating‑system commands, ensuring only a limited set of safe characters can reach those calls. Consider removing or disabling any code paths that accept arbitrary command strings.
  • Implement input validation and sanitization for all data that may influence OS command execution, so that malicious characters are either escaped or rejected, preventing unintended command execution.

Generated by OpenCVE AI on September 25, 2026 at 00:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe campaign
CPEs cpe:2.3:a:adobe:campaign:*:*:*:*:classic:*:*:*
cpe:2.3:a:adobe:campaign:7.4.4:9400:*:*:classic:*:*:*
cpe:2.3:a:adobe:campaign:7.4.4:9401:*:*:classic:*:*:*
Vendors & Products Adobe
Adobe campaign

Tue, 08 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-22T17:39:47.822Z

Reserved: 2026-08-27T21:20:45.367Z

Link: CVE-2026-82004

cve-icon Vulnrichment

Updated: 2026-09-11T20:58:00.334Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:19:59.743

Modified: 2026-09-11T21:17:23.117

Link: CVE-2026-82004

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T00:45:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')